F5 Nginx Plus vulnerabilities
27 known vulnerabilities affecting f5/nginx_plus.
Total CVEs
27
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH14MEDIUM12
Vulnerabilities
Page 2 of 2
CVE-2024-24990HIGHCVSS 7.5vr30vr31+2 more2024-02-14
CVE-2024-24990 [HIGH] CWE-416 CVE-2024-24990: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate.
Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html .
Note: Software versio
nvdf5
CVE-2024-24989HIGHCVSS 7.5vr31≥ R31, < R31 P12024-02-14
CVE-2024-24989 [HIGH] CWE-476 CVE-2024-24989: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate.
Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html .
NOTE: Software versions
nvdf5
CVE-2023-44487HIGHCVSS 7.5KEVPoC≥ r25, < r29vr29+1 more2023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2022-41742HIGHCVSS 7.1≥ R27, < R27-p1≥ R1, < R26-p12022-10-19
CVE-2022-41742 [HIGH] CWE-787 CVE-2022-41742: NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a spe
nvdf5
CVE-2022-41741HIGHCVSS 7.8≥ R27, < R27-p1≥ R1, < R26-p12022-10-19
CVE-2022-41741 [HIGH] CWE-787 CVE-2022-41741: NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a spec
nvdf5
CVE-2022-41743HIGHCVSS 7.0≥ r22, ≤ r27≥ R27, < R27-p1+1 more2022-10-19
CVE-2022-41743 [HIGH] CWE-787 CVE-2022-41743: NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module
NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its crash or potential other impact using a specially crafted audio or video file. The issue affects only NGINX Plus when the hls directive is used in the configuration file.
nvdf5
CVE-2020-5864HIGHCVSS 7.42020-04-23
CVE-2020-5864 [HIGH] CWE-295 CVE-2020-5864: In versions of NGINX Controller prior to 3
CVE-2020-5864: In versions of NGINX Controller prior to 3
In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default.
Affected Products: NGINX Controller, NGINX Plus
Affected Versions: 1.0.1; 2.0.0 - 2.9.0; 3.0.0 - 3.3.0
F5 Advisory Articles: K27205552
F5 References: https://support.f5.com/csp/article/K27205552
f5
← Previous2 / 2